SignatureFlow Privacy Policy
Last updated: August 19, 2026
SignatureFlow ("the extension", "the Service") lets you sign PDF documents and send them to
other people for their electronic signature, from the Chrome extension or the web app.
What data we process
- Account: the name and email you use to create your SignatureFlow account, and your hashed password. If you sign in with Google instead, we receive your name, email and Google account ID from Google - we never see your Google password.
- Documents: the PDF files you upload, along with the signature fields you place on them.
- Recipients: the name and email of the people you send a document to for signature.
- Audit trail: to give each signature legal validity (under ESIGN Act, UETA and eIDAS) we record the IP address, browser (user agent), and date/time of each relevant event (viewed, consented, signed) for every signer.
- Signature: the image or text you draw/type as your signature, which gets embedded in the final PDF.
- Billing: envelopes are purchased one at a time (no subscription). PayPal processes the payment; we only store that the purchase happened and how many envelopes it added to your balance, never your card or bank details.
- Bot protection: when you register from the web app, Cloudflare Turnstile checks your browser is not a bot. This sends your IP address to Cloudflare and returns a pass/fail result to us - we don't receive any other data from it. This check doesn't run in the Chrome extension.
Third parties we use to run the Service
- Cloudflare R2: stores your uploaded and signed PDF files.
- Resend: delivers transactional emails (signing invitations, email verification, password reset).
- PayPal: processes envelope purchases.
- Cloudflare Turnstile: bot detection on the web registration form, as described above.
- Google: only if you choose "Sign in with Google", to verify your identity.
None of these receive your data for advertising purposes, and we don't sell or share your data with anyone else.
Where it's stored
Documents and account data are stored on our server and Cloudflare R2. The Chrome
extension itself does not send data to any third-party server other
than this backend and the providers listed above.
Retention and deletion
Documents and the audit trail are kept while your account is active,
since they form part of the legal evidence of a completed signature.
You can delete your own account at any time from within the app
(click your name/email in the header → "Delete my account"). If you have
no completed (signed) documents, your account is deleted immediately.
If you do, we anonymize it instead of deleting it outright (your name,
email and password are erased, but the signed documents and their audit
trail are kept) - this is required so the legal record of a completed
signature can't be erased by either party after the fact. You can also
email giobarrerac@gmail.com to
request this.
Contact
giobarrerac@gmail.com